[PATCH 1/2] fs/exec: Explicitly unshare fs_struct on exec

Kees Cook keescook at chromium.org
Fri Oct 14 03:54:14 UTC 2022


On Thu, Oct 13, 2022 at 08:18:04PM -0700, Andy Lutomirski wrote:
> But seriously, this makes no sense at all.  It should not be possible to exec a program and then, without ptrace, change its cwd out from under it.  Do we really need to preserve this behavior?

Yup, already abandoned:
https://lore.kernel.org/lkml/202210061301.207A20C8E5@keescook/

-- 
Kees Cook



More information about the Linux-security-module-archive mailing list